Exposed Cloud Functions: A Growing Entry Point for Attackers
Security assessments by Mandiant, part of Google Threat Intelligence, have repeatedly found publicly exposed serverless applications that lack authentication. These are often deployed to meet specific business needs, but they run custom code and third-party packages that can be vulnerable to attacks such as local and remote file inclusion. If exploited, attackers can gain control of the underlying container, potentially leading to a full compromise of the victim's cloud environment.
Serverless computing, also known as Function-as-a-Service, lets businesses run small pieces of code without managing servers. It underpins e-commerce, media, payment processing, and increasingly, AI tools like chatbots and automated agents. As generative AI adoption grows, so does reliance on serverless functions, making these environments a more attractive target for attackers.
Once attackers gain access through an exposed function, they often look for ways to escalate their access or move further into the network. This can include extracting secrets stored in application code or examining application logic and data to find additional weaknesses to exploit.